CVE-2026-59309
CRITICAL · 9.8 EPSS 0.7%vendor patched urgently, advisory published, but KEV absence and no confirmed wild exploitation.
What: VMware vCenter authentication bypass in Directory Service (CVSS 9.8 CRITICAL); network-accessible, no credentials required for unauthorized system access.
Why it matters: Broadcom issued urgent security advisory VMSA-2026-0006 on 29 July 2026 addressing this flaw alongside CVE-2026-59310 (RCE, 9.8). Rapid7 published analysis same day. No KEV listing yet, but patch availability and immediate vendor urgency signal active remediation posture. Multiple critical VMware flaws bundled suggest coordinated disclosure.
Where it's seen: Security advisories, vendor patch announcements, security researcher blogs (Rapid7 ETR), aggregator posts and threat feeds. Chatter focuses on patch urgency and attack surface (vCenter appliances exposed to network). No public PoC or in-the-wild exploitation reported.
RISK: CRITICAL — vCenter is foundational infrastructure; auth bypass allows full system compromise with no credentials.
Description
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. A malicious actor with network access to vCenter may exploit this issue to bypass authentication and gain unauthorized access to the system.
CVSS 3.1 breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H- Attack vector
- Network
- Complexity
- Low
- Privileges required
- None
- User interaction
- None
- Scope
- Unchanged
- Confidentiality
- High
- Integrity
- High
- Availability
- High